Skip to main content
POST
Error

Authorizations

Authorization
string
header
required

The control surface credential. Send Authorization: Bearer <token>.

Two kinds of token are accepted and they are told apart by shape, not by a separate header. A token beginning pbk_ is an org scoped API key, whose public half and secret half are generated together and of which only a hash of the secret is ever stored; anything else is treated as an OAuth 2.1 access token and verified against the authorization server's keys.

Both resolve to the same context: an org, a principal and a set of scopes. Nothing downstream branches on which channel you used, with one deliberate exception, key management, which requires a signed-in person so that a key can never mint another key.

Scopes are enforced when MCP tools are REGISTERED rather than when they are called, so a tool your credential cannot use is absent from tools/list rather than refused mid gesture.

Path Parameters

deviceId
string
required

The deviceId from a listing.

Response

A live session. Hand the whole body to the browser's video SDK.

token
string
required

A short-lived vendor SDK credential for the media stream. Do not store it.

baseUrl
string
required

The RTC endpoint the SDK connects to.

padCode
string
required

The device's vendor instance code.

userId
string
required

A stable, sanitized per-person id for the SDK. It carries no secret.

resolution
integer
required

The SDK resolution profile: 16 selects 720x1920, then the SDK aligns to the real ratio.